Approved Scanning Vendor
An Approved Scanning Vendor (ASV) is an organization that the PCI Security Standards Council has authorized to perform external vulnerability scans of an organization's internet-facing systems as part of PCI DSS compliance. Before a vendor can appear on the Council's official list, its scanning solution must be tested and approved by the PCI SSC. Organizations that need such scans can locate qualified vendors through the official list maintained by the PCI Security Standards Council.
An Approved Scanning Vendor (ASV) is an organization qualified by the PCI Security Standards Council (PCI SSC) to deploy an ASV scan solution—security services and tools used to conduct external vulnerability scanning against systems in scope for the Payment Card Industry Data Security Standard (PCI DSS). Qualification is contingent on the vendor's scan solution being tested and approved by PCI SSC prior to inclusion on the Council's List of Approved Scanning Vendors, and on staff and security personnel completing the associated ASV training and qualification program. ASV status pertains specifically to external scanning obligations under PCI DSS and is distinct from other PCI SSC roles such as Qualified Security Assessors (QSAs); it reflects a contractual/scheme-based qualification within the PCI DSS framework rather than a statutory legal designation. The canonical designation is 'Approved Scanning Vendor'; the variant 'Authorized Scanning Vendor' appears informally but is not the official PCI SSC term. ASV program requirements, versions, and the vendor list change over time, so readers should verify current status and requirements against the official PCI SSC source.
Why it matters
External vulnerability scanning is a recurring obligation within the PCI DSS framework for organizations with internet-facing systems in scope for the standard. Because PCI DSS is a scheme-based, contractual set of requirements rather than a statutory law, the party performing these scans generally cannot be just any security firm—the scanning solution must be one that the PCI Security Standards Council has tested and approved. The ASV designation exists to give organizations a reliable way to identify vendors whose scanning solutions have passed this vetting, reducing the risk that a scan is later rejected as non-conforming when compliance is assessed or reported to acquirers and payment brands.
For compliance and information security teams, using an approved vendor matters because the results of ASV scanning typically feed into an organization's demonstration of PCI DSS compliance. Selecting a vendor not on the Council's official list may leave an organization unable to satisfy the external scanning requirement, forcing rework. It is worth emphasizing that ASV status reflects qualification within the PCI DSS scheme; it is not a legal license or a government designation, and it does not by itself establish overall PCI DSS compliance—it addresses only the external scanning portion.
Because ASV program requirements, versions, and the list of approved vendors change over time, teams should verify a vendor's current status against the official PCI SSC source rather than relying on prior engagements or third-party recommendations. Notably, payment service providers such as Adyen have stated that they cannot recommend a specific ASV, since the scanning engagement must be performed independently by an approved vendor.
Who it's relevant to
Inside ASV
Common questions
Answers to the questions practitioners most commonly ask about ASV.

